Linux Netfilter discussions
 help / color / mirror / Atom feed
* How to block a range of IPs?
@ 2003-04-27  6:11 Afshin Lamei
  2003-04-27  7:25 ` Michael K
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Afshin Lamei @ 2003-04-27  6:11 UTC (permalink / raw)
  To: netfilter

Hi,
How can I write a rule for a custom range of IPs? for example, I want to 
block every WWW packet incoming from eth1, which source is an IP between 
192.168.1.10 and 192.168.1.20.
please help me writing an example.
thank you
afshin





_________________________________________________________________
Help STOP SPAM with the new MSN 8 and get 2 months FREE*  
http://join.msn.com/?page=features/junkmail



^ permalink raw reply	[flat|nested] 9+ messages in thread
* RE: iptables with LDAP authentication
@ 2003-04-30  1:05 Khanh Tran
  2003-04-30 13:40 ` Stefan Nehlsen
  0 siblings, 1 reply; 9+ messages in thread
From: Khanh Tran @ 2003-04-30  1:05 UTC (permalink / raw)
  To: yogesh, netfilter

Check out: 

http://www.linuxselfhelp.com/HOWTO/Authentication-Gateway-HOWTO/setup.html

Scroll down to the 3.2 section.  It has a link to a iptables PAM that
supposedly will insert the proper iptables lines to allow the authenticated
client access through the firewall.  Hope this helps...

Khanh Tran
Network Operations
Sarah Lawrence College


-----Original Message-----
From: Yogesh Subhash Talekar [mailto:yogesh@unipune.ernet.in]
Sent: Monday, April 28, 2003 8:35 AM
To: netfilter@lists.netfilter.org
Subject: iptables with LDAP authentication


hi,

I have a full Class C real IP network. All department have their own Linux
servers and the last IP (X.X.X.254) is given to the CISCO router which is
our gateway to Internet. Currently i have a OpenBSD firewall configured as
bridge with IP-filter.

Now I want to go with Linux firewall, if it will have following features:

1. It will run IP-tables firewall and will authenticate everyone (rather
each session for each type of service .. http, ftp, ssh etc.) against the
central LDAP server which is on some other server.

2. It will put on bandwidth restriction on each campus departmental
server. (it is possible with tc/qdisc)

All I want to know is ... is it possible to authenticate the traffic
flowing thro' a Linux ip-tables bridging firewall against a central
OpenLDAP database?
Will it maintain the sessions for each user separately for HTTP (Squid?),
FTP and telnet or ssh ? Is it possible to log per head traffic and ban
them if the exceed some limit (say 200 MB per month).

Any suggestions/ links / advice will be highly appriciated.

thanks in advance

--yogesh







^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2003-04-30 13:40 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-04-27  6:11 How to block a range of IPs? Afshin Lamei
2003-04-27  7:25 ` Michael K
2003-04-27 10:42   ` Martin Josefsson
2003-04-28 12:34     ` iptables with LDAP authentication Yogesh Subhash Talekar
2003-04-29  3:54       ` Alex Nee
2003-04-27  9:26 ` How to block a range of IPs? Cedric Blancher
2003-04-27 11:45 ` FWD: " Julius Wijaya
  -- strict thread matches above, loose matches on Subject: below --
2003-04-30  1:05 iptables with LDAP authentication Khanh Tran
2003-04-30 13:40 ` Stefan Nehlsen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox